|
|
Subscribe / Log in / New account

Mageia alert MGASA-2020-0426 (libexif)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2020-0426: Updated libexif packages fix a security vulnerability
Date:  Sun, 15 Nov 2020 16:46:10 +0100
Message-ID:  <20201115154610.1638A9F6EB@duvel.mageia.org>
Archive-link:  Article

MGASA-2020-0426 - Updated libexif packages fix a security vulnerability Publication date: 15 Nov 2020 URL: https://advisories.mageia.org/MGASA-2020-0426.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-0452 Description: In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation. (CVE-2020-0452) References: - https://bugs.mageia.org/show_bug.cgi?id=27592 - https://www.debian.org/security/2020/dsa-4786 - https://ubuntu.com/security/notices/USN-4624-1 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0452 SRPMS: - 7/core/libexif-0.6.22-1.2.mga7


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds